User/Command/ConfirmEmailHandler.php in Flarum before 0.1.0-beta.8 mishandles invalidation of user email tokens.
The product does not properly “clean up” and remove temporary or supporting resources after they have been used.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Flarum | Flarum | 0.1.0 (including) | 0.1.0 (including) |
Flarum | Flarum | 0.1.0-beta (including) | 0.1.0-beta (including) |
Flarum | Flarum | 0.1.0-beta2 (including) | 0.1.0-beta2 (including) |
Flarum | Flarum | 0.1.0-beta3 (including) | 0.1.0-beta3 (including) |
Flarum | Flarum | 0.1.0-beta4 (including) | 0.1.0-beta4 (including) |
Flarum | Flarum | 0.1.0-beta5 (including) | 0.1.0-beta5 (including) |
Flarum | Flarum | 0.1.0-beta6 (including) | 0.1.0-beta6 (including) |
Flarum | Flarum | 0.1.0-beta7 (including) | 0.1.0-beta7 (including) |
Flarum | Flarum | 0.1.0-beta7.1 (including) | 0.1.0-beta7.1 (including) |
Flarum | Flarum | 0.1.0-beta7.2 (including) | 0.1.0-beta7.2 (including) |